CVE-2023-39978
published 2023-08-08CVE-2023-39978: ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
PriorityP48low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.31%
23.6th percentile
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | — | — |
| fedoraproject | fedora | — | — |
| imagemagick | imagemagick | < 6.9.12-91 | 6.9.12-91 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j6x7-7g72-8ww2: ImageMagick before 6
ghsa_unreviewed·2023-08-08
CVE-2023-39978 [LOW] CWE-401 GHSA-j6x7-7g72-8ww2: ImageMagick before 6
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
OSV
CVE-2023-39978: ImageMagick before 6
osv·2023-08-08·CVSS 3.3
CVE-2023-39978 [LOW] CVE-2023-39978: ImageMagick before 6
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Red Hat
ImageMagick: Memory leak in Magick::Draw
vendor_redhat·2023-08-08·CVSS 3.3
CVE-2023-39978 [LOW] CWE-401 ImageMagick: Memory leak in Magick::Draw
ImageMagick: Memory leak in Magick::Draw
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2023-39978: imagemagick - ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memo...
vendor_debian·2023·CVSS 3.3
CVE-2023-39978 [LOW] CVE-2023-39978: imagemagick - ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memo...
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ImageMagick/ImageMagick6/commit/c90e79b3b22fec309cab55af2ee606f71b027b12https://github.com/ImageMagick/ImageMagick6/compare/6.9.12-90...6.9.12-91https://github.com/rmagick/rmagick/pull/1406/fileshttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/https://github.com/ImageMagick/ImageMagick6/commit/c90e79b3b22fec309cab55af2ee606f71b027b12https://github.com/ImageMagick/ImageMagick6/compare/6.9.12-90...6.9.12-91https://github.com/rmagick/rmagick/pull/1406/fileshttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/
2023-08-08
Published